PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
Icon: Size: 5,68 MBSHA-256 Hash: B8CF4FC945A0C0401F6931467F4DDF2F58A017E932A87B3DDAA0BB925EF78231 SHA-1 Hash: 41E707866B91BF5509091B0949FCCAA8CBE73908 MD5 Hash: 6A0748CEF7672D8C10DA160A9F9D3E7C Imphash: BA5546933531FAFA869B1F86A4E2A959 MajorOSVersion: 5 MinorOSVersion: 2 CheckSum: 005BB998 EntryPoint (rva): A6A0 SizeOfHeaders: 400 SizeOfImage: 64000 ImageBase: 0000000140000000 Architecture: x64 ImportTable: 3BB94 IAT: 2A000 Characteristics: 22 TimeDateStamp: 66E87CD8 Date: 16/09/2024 18:45:44 File Type: EXE Number Of Sections: 7 ASLR: Disabled Section Names (Optional Header): .text, .rdata, .data, .pdata, _RDATA, .rsrc, .reloc Number Of Executable Sections: 1 Subsystem: Windows Console UAC Execution Level Manifest: asInvoker |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
400 | 28A00 | 1000 | 28890 |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
28E00 | 12800 | 2A000 | 1271A |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
3B600 | E00 | 3D000 | 103F8 |
|
|
| .pdata | 0x40000040 Initialized Data Readable |
3C400 | 2200 | 4E000 | 20E8 |
|
|
| _RDATA | 0x40000040 Initialized Data Readable |
3E600 | 200 | 51000 | 15C |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
3E800 | 11000 | 52000 | 10EB6 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
4F800 | 800 | 63000 | 75C |
|
|
| Binder/Joiner/Crypter |
| Dropper code detected (EOF) - 5,29 MB |
| Entry Point |
The section number (1) have the Entry Point Information -> EntryPoint (calculated) - 9AA0 Code -> 4883EC28E8670200004883C428E96AFEFFFFCCCCCCCCCCCCCCCCCCCCCCCCCCCC4883EC28E8AF07000085C0742165488B0425 Assembler |SUB RSP, 0X28 |CALL 0X14000A910 |ADD RSP, 0X28 |JMP 0X14000A51C |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |SUB RSP, 0X28 |CALL 0X14000AE78 |TEST EAX, EAX |JE 0X14000A6EE |
| Signatures |
| Rich Signature Analyzer: Code -> C7A91E8483C870D783C870D783C870D7C8B073D684C870D7C8B075D63DC870D7C8B074D689C870D7CCB48DD780C870D7CCB475D6ABC870D7CCB474D692C870D7CCB473D68AC870D7C8B071D686C870D783C871D7F6C870D742B474D697C870D742B472D682C870D75269636883C870D7 Footprint md5 Hash -> 06764C53FA54C90C6F35C5AC28ACAF10 • The Rich header apparently has not been modified Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Detect It Easy (die) • PE+(64): packer: PyInstaller(-)[-] • PE+(64): compiler: Microsoft Visual C/C++(-)[-] • PE+(64): linker: Microsoft Linker(14.34**)[-] • PE+(64): overlay: zlib archive(-)[-] • Entropy: 7.97916 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | IsDebuggerPresent | Determines if the calling process is being debugged by a user-mode debugger. |
| File Access |
| %s%c%s.exe 6python310.dll bpython310.dll blibssl-1_1.dll blibcrypto-1_1.dll bVCRUNTIME140.dll ADVAPI32.dll KERNEL32.dll Path of ucrtbase.dll ucrtbase.dll .dat @.dat xbase_library.zip base_library.zip Temp |
| File Access (UNICODE) |
| mscoree.dll |
| Interest's Words |
| exec attrib start ping expand replace |
| URLs |
| http://schemas.microsoft.com/SMI/2016/WindowsSettings |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Ascii | WinAPI Sockets (connect) |
| Text | Ascii | File (GetTempPath) |
| Text | Ascii | File (CreateFile) |
| Text | Ascii | File (WriteFile) |
| Text | Ascii | File (ReadFile) |
| Text | Ascii | Anti-Analysis VM (IsDebuggerPresent) |
| Text | Ascii | Reconnaissance (FindNextFileW) |
| Text | Ascii | Reconnaissance (FindClose) |
| Text | Ascii | Stealth (CloseHandle) |
| Text | Ascii | Execution (CreateProcessW) |
| Entry Point | Hex Pattern | LX-Exe Executable Image |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8.0 (DLL) |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8.0 |
| Entry Point | Hex Pattern | PE-Exe Executable Image |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \ICON\1\0 | 520E8 | 10828 | 3E8E8 | 2800000080000000000100000100200000000000000001001C7600001C760000000000000000000000000000000000000000 | (............. ..........v...v.................... |
| \GROUP_ICON\0\0 | 62910 | 14 | 4F110 | 0000010001008080000001002000280801000100 | ............ .(..... |
| \24\1\0 | 62924 | 592 | 4F124 | 3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E653D2279 | <?xml version="1.0" encoding="UTF-8" standalone="y |
| Intelligent String |
| • %s%c%s.pkg • %s%c%s.exe • ucrtbase.dll • base_library.zip • status_texttk.tcl • .exe • .cmd • .bat • .com • mscoree.dll • .bss • ADVAPI32.dll • <longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware> • .rMh • X.qNJ • b_bz2.pyd • b_decimal.pyd • b_hashlib.pyd • b_lzma.pyd • b_socket.pyd • b_ssl.pyd • blibcrypto-1_1.dll • blibssl-1_1.dll • bpython310.dll • bselect.pyd • bunicodedata.pyd • xbase_library.zip • zPYZ-00.pyz • 6python310.dll |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 10D7 | N/A | .text | CALL QWORD PTR [RIP+0x2841B] |
| 1939 | N/A | .text | CALL QWORD PTR [RIP+0x27E21] |
| 196E | N/A | .text | CALL QWORD PTR [RIP+0x27DEC] |
| 1A11 | N/A | .text | CALL QWORD PTR [RIP+0x27D49] |
| 1A2E | N/A | .text | CALL QWORD PTR [RIP+0x27D2C] |
| 1A3E | N/A | .text | CALL QWORD PTR [RIP+0x27D1C] |
| 1A51 | N/A | .text | CALL QWORD PTR [RIP+0x27D09] |
| 1A77 | N/A | .text | CALL QWORD PTR [RIP+0x27CE3] |
| 1A8D | N/A | .text | CALL QWORD PTR [RIP+0x27CCD] |
| 1AFD | N/A | .text | CALL QWORD PTR [RIP+0x27C5D] |
| 1B2F | N/A | .text | CALL QWORD PTR [RIP+0x27C2B] |
| 1DD5 | N/A | .text | CALL QWORD PTR [RIP+0x2770D] |
| 2101 | N/A | .text | CALL QWORD PTR [RIP+0x273D9] |
| 2336 | N/A | .text | CALL QWORD PTR [RIP+0x2719C] |
| 2375 | N/A | .text | CALL QWORD PTR [RIP+0x2715D] |
| 239A | N/A | .text | CALL QWORD PTR [RIP+0x27138] |
| 23BF | N/A | .text | CALL QWORD PTR [RIP+0x27113] |
| 23E7 | N/A | .text | CALL QWORD PTR [RIP+0x270EB] |
| 240F | N/A | .text | CALL QWORD PTR [RIP+0x270C3] |
| 2437 | N/A | .text | CALL QWORD PTR [RIP+0x2709B] |
| 245F | N/A | .text | CALL QWORD PTR [RIP+0x27073] |
| 2487 | N/A | .text | CALL QWORD PTR [RIP+0x2704B] |
| 24B7 | N/A | .text | CALL QWORD PTR [RIP+0x2701B] |
| 24DF | N/A | .text | CALL QWORD PTR [RIP+0x26FF3] |
| 2507 | N/A | .text | CALL QWORD PTR [RIP+0x26FCB] |
| 252F | N/A | .text | CALL QWORD PTR [RIP+0x26FA3] |
| 2557 | N/A | .text | CALL QWORD PTR [RIP+0x26F7B] |
| 257F | N/A | .text | CALL QWORD PTR [RIP+0x26F53] |
| 25A7 | N/A | .text | CALL QWORD PTR [RIP+0x26F2B] |
| 25CF | N/A | .text | CALL QWORD PTR [RIP+0x26F03] |
| 25F7 | N/A | .text | CALL QWORD PTR [RIP+0x26EDB] |
| 261F | N/A | .text | CALL QWORD PTR [RIP+0x26EB3] |
| 2647 | N/A | .text | CALL QWORD PTR [RIP+0x26E8B] |
| 266F | N/A | .text | CALL QWORD PTR [RIP+0x26E63] |
| 2697 | N/A | .text | CALL QWORD PTR [RIP+0x26E3B] |
| 26BF | N/A | .text | CALL QWORD PTR [RIP+0x26E13] |
| 26E7 | N/A | .text | CALL QWORD PTR [RIP+0x26DEB] |
| 270F | N/A | .text | CALL QWORD PTR [RIP+0x26DC3] |
| 2737 | N/A | .text | CALL QWORD PTR [RIP+0x26D9B] |
| 275F | N/A | .text | CALL QWORD PTR [RIP+0x26D73] |
| 2787 | N/A | .text | CALL QWORD PTR [RIP+0x26D4B] |
| 27AF | N/A | .text | CALL QWORD PTR [RIP+0x26D23] |
| 27D7 | N/A | .text | CALL QWORD PTR [RIP+0x26CFB] |
| 27FF | N/A | .text | CALL QWORD PTR [RIP+0x26CD3] |
| 2827 | N/A | .text | CALL QWORD PTR [RIP+0x26CAB] |
| 284F | N/A | .text | CALL QWORD PTR [RIP+0x26C83] |
| 2877 | N/A | .text | CALL QWORD PTR [RIP+0x26C5B] |
| 289F | N/A | .text | CALL QWORD PTR [RIP+0x26C33] |
| 28C7 | N/A | .text | CALL QWORD PTR [RIP+0x26C0B] |
| 28EF | N/A | .text | CALL QWORD PTR [RIP+0x26BE3] |
| 2917 | N/A | .text | CALL QWORD PTR [RIP+0x26BBB] |
| 293F | N/A | .text | CALL QWORD PTR [RIP+0x26B93] |
| 2967 | N/A | .text | CALL QWORD PTR [RIP+0x26B6B] |
| 298F | N/A | .text | CALL QWORD PTR [RIP+0x26B43] |
| 29B7 | N/A | .text | CALL QWORD PTR [RIP+0x26B1B] |
| 29DF | N/A | .text | CALL QWORD PTR [RIP+0x26AF3] |
| 2A07 | N/A | .text | CALL QWORD PTR [RIP+0x26ACB] |
| 2A2F | N/A | .text | CALL QWORD PTR [RIP+0x26AA3] |
| 2A57 | N/A | .text | CALL QWORD PTR [RIP+0x26A7B] |
| 2A7F | N/A | .text | CALL QWORD PTR [RIP+0x26A53] |
| 2AA7 | N/A | .text | CALL QWORD PTR [RIP+0x26A2B] |
| 2ACF | N/A | .text | CALL QWORD PTR [RIP+0x26A03] |
| 2AF7 | N/A | .text | CALL QWORD PTR [RIP+0x269DB] |
| 2B1F | N/A | .text | CALL QWORD PTR [RIP+0x269B3] |
| 2B47 | N/A | .text | CALL QWORD PTR [RIP+0x2698B] |
| 2B6F | N/A | .text | CALL QWORD PTR [RIP+0x26963] |
| 2B97 | N/A | .text | CALL QWORD PTR [RIP+0x2693B] |
| 2BBF | N/A | .text | CALL QWORD PTR [RIP+0x26913] |
| 2C0D | N/A | .text | CALL QWORD PTR [RIP+0x26B4D] |
| 2C23 | N/A | .text | CALL QWORD PTR [RIP+0x26B37] |
| 2C35 | N/A | .text | JMP QWORD PTR [RIP+0x26B25] |
| 2C75 | N/A | .text | CALL QWORD PTR [RIP+0x26AE5] |
| 2CAD | N/A | .text | CALL QWORD PTR [RIP+0x26AAD] |
| 2CF9 | N/A | .text | CALL QWORD PTR [RIP+0x26A61] |
| 2D15 | N/A | .text | CALL QWORD PTR [RIP+0x26A45] |
| 2D36 | N/A | .text | CALL QWORD PTR [RIP+0x26A24] |
| 2D48 | N/A | .text | CALL QWORD PTR [RIP+0x26A12] |
| 2D55 | N/A | .text | CALL QWORD PTR [RIP+0x26A05] |
| 2DFF | N/A | .text | CALL QWORD PTR [RIP+0x2695B] |
| 2E1C | N/A | .text | CALL QWORD PTR [RIP+0x2693E] |
| 2E2F | N/A | .text | CALL QWORD PTR [RIP+0x2692B] |
| 2E43 | N/A | .text | CALL QWORD PTR [RIP+0x26917] |
| 2E64 | N/A | .text | CALL QWORD PTR [RIP+0x268F6] |
| 2E79 | N/A | .text | CALL QWORD PTR [RIP+0x268E1] |
| 3126 | N/A | .text | CALL QWORD PTR [RIP+0x26634] |
| 32E3 | N/A | .text | CALL QWORD PTR [RIP+0x26477] |
| 3324 | N/A | .text | CALL QWORD PTR [RIP+0x26436] |
| 33E4 | N/A | .text | CALL QWORD PTR [RIP+0x26376] |
| 33F8 | N/A | .text | CALL QWORD PTR [RIP+0x26362] |
| 340D | N/A | .text | CALL QWORD PTR [RIP+0x2634D] |
| 3421 | N/A | .text | CALL QWORD PTR [RIP+0x26339] |
| 3454 | N/A | .text | CALL QWORD PTR [RIP+0x26306] |
| 3486 | N/A | .text | CALL QWORD PTR [RIP+0x262D4] |
| 34F4 | N/A | .text | CALL QWORD PTR [RIP+0x26266] |
| 3530 | N/A | .text | CALL QWORD PTR [RIP+0x2622A] |
| 354C | N/A | .text | CALL QWORD PTR [RIP+0x2620E] |
| 3563 | N/A | .text | CALL QWORD PTR [RIP+0x261F7] |
| 3577 | N/A | .text | CALL QWORD PTR [RIP+0x261E3] |
| 35B3 | N/A | .text | CALL QWORD PTR [RIP+0x261A7] |
| 35C8 | N/A | .text | CALL QWORD PTR [RIP+0x26192] |
| 38045E-38046B | N/A | *padding* | Potential obfuscated jump sequence detected, count: 7 |
| 3837BC-3837CB | N/A | *padding* | Potential obfuscated jump sequence detected, count: 8 |
| 38DF6C-38DFBB | N/A | *padding* | Potential obfuscated jump sequence detected, count: 40 |
| 39AA56-39AA63 | N/A | *padding* | Potential obfuscated jump sequence detected, count: 7 |
| 3AFE1E-3AFE2E | N/A | *padding* | Potential obfuscated jump sequence detected, count: 7 |
| 49A475-49A48E | N/A | *padding* | Potential obfuscated jump sequence detected, count: 13 |
| 50000 | N/A | *Overlay* | 78DA5D8FC16EC2300C40E3B69454ADB4FD4627C4 | x.]..n.0.@...T...F'. |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 4038944 | 67,7987% |
| Null Byte Code | 99028 | 1,6623% |
© 2026 All rights reserved.